UK ICO Issues Guidance On How To Deal With Data Protection Complaints

Share this Article:

From 19 June 2026, all UK organisations must have a process to handle data protection complaints internally. This is part of the new Data (Use and Access) Act 2025 and is designed to make sure complaints about personal data are dealt with quickly and fairly.

Previously, most complaints went straight to the Information Commissioner’s Office (ICO), which created a backlog of around 40 weeks before cases were assigned. The new rules mean businesses must take responsibility for complaints themselves. If a complaint cannot be resolved internally, it can then be escalated to the ICO.

What you need to do

Organisations must make it easy for people to raise a complaint. This could be through an online form, email, post, phone, live chat, or in person. The key is that individuals must be able to submit a complaint in whatever way works best for them. Social media can also be used if the organisation has an online presence.

Once a complaint is received, it must be acknowledged within 30 days. This should confirm the complaint has been received and explain what happens next.

The organisation must investigate the complaint promptly and keep the complainant informed. Once a decision has been made, the outcome must be communicated clearly and without delay.

Understanding ICO guidance

The ICO uses three terms in its guidance. Must refers to legal obligations that organisations cannot ignore. Should is considered best practice and is expected unless there is a good reason not to follow it. Could highlights optional steps or examples that may help organisations comply more effectively. Understanding these distinctions helps businesses plan their complaints process confidently.

Keeping a full log and assigning responsibility

Keeping a full record of complaints is essential. Logs should show how complaints were received, the steps taken to resolve them and the outcomes. This not only demonstrates compliance but can also highlight patterns that help prevent future issues. Assign responsibility for complaints handling to a named person or team to ensure accountability and that deadlines are met.

Benefits of planning ahead

A clear complaints process is not just a legal obligation. It strengthens trust with customers and staff, shows that the organisation takes personal data seriously and can reduce the number of complaints that escalate to the ICO. It also gives teams the chance to resolve issues efficiently and learn from complaints to improve internal processes.

Why Professional Support Can Help

For many organisations, especially those without dedicated privacy teams, implementing a compliant complaints process may feel complex. This is where seeking professional guidance can be invaluable. At Privacy Helper, we can support businesses in designing robust complaint-handling frameworks, training staff and ensuring policies align with the ICO’s expectations. Getting expert advice early can help organisations avoid rushed implementation and reduce the risk of non-compliance.

Practical steps to take now

To get ready by June 2026, organisations should:

  • Review how complaints are currently received

  • Update or create a complaints handling procedure

  • Train staff to identify and escalate complaints correctly

  • Keep a log of complaints and track deadlines to make sure responses are timely

Even if a business does not have a dedicated privacy team, taking these steps early makes it easier to comply and reduces the risk of mistakes.

Need Help with ICO Complaint Compliance?

  • Contact us now.
  • We provide expert support to implement complaint-handling processes and ensure your policies meet ICO standards, all in a simple, straightforward way.

About the Author:

Explore More Articles